The Kryptos tableau

Kryptos is a sculpture at CIA headquarters with four encrypted messages. The first, K1, is a Vigenère cipher. Below are its ciphertext as carved and the table from the sculpture. Decode it one letter at a time.

Row of the key letter → find the cipher letter → read the top of its column.

 

0 / 63

Each ciphertext letter has a key letter above it. Step through and watch the tableau.

Four messages, one still unsolved.

Jim Sanborn made Kryptos for CIA headquarters in Langley, Virginia. It was dedicated in 1990. Ed Scheidt, a retired head of the CIA’s Office of Communications, helped him design the ciphers.

The left half of the copper screen holds about 870 characters in four sections, K1 to K4. The right half holds the table used in the tool above.

  • K1 and K2 are Vigenère ciphers with the keys PALIMPSEST and ABSCISSA.
  • K3 is a transposition. Its letters are reordered, not replaced.
  • K4 has 97 characters and is unsolved. Sanborn has published four words of its plaintext as hints: BERLIN, CLOCK, EAST and NORTHEAST.

An NSA team solved the first three in 1992 but kept it internal. CIA analyst David Stein solved them by hand in 1998. Jim Gillogly was the first to publish a solution, in 1999.

K1 reads “Between subtle shading and the absence of light lies the nuance of iqlusion”. The misspelling is on the sculpture. Sanborn has said such errors are intentional.

How the key hides letter frequencies.

A simple substitution cipher replaces each letter with the same other letter every time. Frequency analysis breaks it. E is the most common letter in English, so the most common cipher letter is probably E.

Vigenère changes the substitution at every position. The key letter picks the row of the table. With PALIMPSEST, letter 1 uses row P, letter 2 uses row A, and letter 11 uses row P again.

In K1, the plaintext has ten E’s. They become six different cipher letters: M, P, H, Y, I and L. In reverse, the cipher letter Q stands for O, L or H. Counting cipher letters no longer points to E.

The rows on Kryptos also start from the word KRYPTOS instead of A. The ordinary A–Z table with the correct key turns K1 into nonsense.

Giovan Battista Bellaso described the method in 1553. It was later named after Blaise de Vigenère and went unbroken for about 300 years.

The repeating key gives it away.

The key repeats every 10 letters. When the same plaintext meets the same part of the key, it gives the same ciphertext.

K1 has one such repeat. VJYQT appears at positions 31 and 51. Both times it encodes NCEOF, from “absence of” and “nuance of”, and both times the key starts at P.

The distance is 20, so the key length divides 20: 2, 4, 5, 10 or 20. Friedrich Kasiski published this test in 1863.

Once the length is known, split the text into 10 columns. Letters 1, 11, 21… all use row P. Each column is a simple substitution again, and frequency analysis works. K1 is short, with six or seven letters per column, so this step still needs guessing. On longer messages it is routine.

How the Vigenère cipher is broken